@inproceedings{li2019nattack,
  title={Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks},
  author={Li, Yandong and Li, Lijun and Wang, Liqiang and Zhang, Tong and Gong, Boqing},
  booktitle={International Conference on Machine Learning},
  pages={3866--3876},
  year={2019},
  organization={PMLR}
}